Mullvad Kills Its Public Encrypted DNS, Redirects Funding to Quad9
Mullvad is retiring the public DNS-over-HTTPS servers it has run since 2022, arguing it makes little sense to duplicate work that the Quad9 Foundation already does better. The company will instead financially back Quad9 as its recommended public resolver. The servers were always redundant for Mullvad VPN users, whose queries are handled internally over the encrypted tunnel; their value was outside the VPN, where Mullvad Browser used them by default and where anyone could point their DNS at them to keep an ISP from logging visited domains.
The cutover has concrete deadlines and manual steps. Anyone who hand-configured Mullvad’s DoH endpoints must switch to Quad9 before November 2, 2026, using Quad9’s setup guides. Mullvad Browser users on default or ad-blocking DoH settings get migrated automatically, but customized configurations are left untouched and must be reset by the user. Existing iOS and macOS DoH configuration profiles will simply stop working and need to be replaced with Quad9’s equivalents.
The move reflects a growing recognition that running a hardened, privacy-respecting public resolver is a specialized operation with real costs, and that consolidating support behind an established nonprofit may serve users better than a partial in-house effort. The trade-off is added centralization of encrypted DNS around a single provider, and a migration burden that falls on the subset of users who strayed from the defaults.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.